IT Security Control Library

Collapsible control set with criticality, effort, ownership, assessment metrics, vendor security asks and the traps that actually cost people findings — mapped across NIST SP 800-53 Rev. 5, SP 800-171, SP 800-172, the SSDF (SP 800-218) and FDA premarket expectations, data protection law, ISO/IEC 27001:2022, SOC 2 and SOX IT general controls, each carrying a ten-dimension impact profile across CIA, privacy, financial, regulatory, GDPR, SEC, market and operational exposure.

0Controls shown
0Domains
0Framework refs
0Criticality 5
0Weighted coverage
0Tooling options
Search
Lens
High impact in
Criticality
Org size
Footprint
RMF step
Domain
How to score, and what the framework lenses actually mean
RMF assessment scoring

SP 800-53A assesses at the objective level, not the control level. Each control decomposes into determination statements, and each is judged Satisfied or Other than satisfied using examine, interview and test. A control is only met when every objective under it is met — partial credit does not exist at the control level, which is why the Metric field below is written as something countable rather than as a yes/no.

Assess frequency should follow criticality: score-5 controls on a continuous or quarterly cycle, score-2 controls annually. That is your SP 800-137 continuous monitoring strategy in practice.

CMMC / 800-171 scoring

Different arithmetic. 110 requirements decompose into 320 assessment objectives, each scored MET, NOT MET or NOT APPLICABLE. A requirement is MET only when all its objectives are MET. SPRS scoring starts at 110 and subtracts 5, 3 or 1 point per unmet requirement by weight, floor of −203.

Evidence must be both adequate (the right kind of thing) and sufficient (enough of it). Those are separate tests and assessors fail people on the second one far more often than the first.

Reading the lenses

800-171 chips use Rev. 2 identifiers (3.1.1), because that is what CMMC assesses against today. Rev. 3 renumbers to 03.01.01 and consolidates some requirements; the DoD transition runs through rulemaking rather than automatically, so do not switch your evidence numbering ahead of the contract clause.

800-172 chips are the enhanced requirements, relevant only at CMMC Level 3 and only for the subset of assets carrying the highest-value CUI.

SSDF / FDA combines SP 800-218 practice IDs with the FDA premarket expectations under FD&C Act §524B. Both point at the same underlying secure development discipline.

Reading the impact profile

Ten dimensions, each scored / Low / Moderate / High, answering one question: if this control fails or is absent, how bad is the exposure there. The strip on each row runs in a fixed order — Confidentiality, Integrity, Availability, Privacy, Financial, Regulatory, EU/GDPR fines, SEC disclosure and ICFR, Market and stock price, Operational.

The High impact in filter narrows to controls scoring High in every dimension you select, so combining GDPR and SEC gives you the intersection rather than the union. Regulatory is deliberately the broadest dimension, because for a regulated organisation most security failures carry some enforcement exposure; use it alongside a second dimension rather than on its own.

These are scored for a mid-to-large regulated organisation. Adjust them for your own context — a private company has no SEC dimension, and a US-only business can discount the GDPR column entirely.

IT SOX / ITGC

The SOX lens uses the four ITGC domains an external auditor works in: APD access to programs and data, PC program change, PD program development, CO computer operations — plus IPE for information produced by the entity, CUEC for complementary user entity controls inherited from a SOC 1, and COSO 2013 principle numbers. Principle 11 is the ITGC principle and appears most often.

The test is different from every other lens here. Not 'is this secure' but 'can the financial statements be relied upon'. Population completeness comes first, then the control. A deficiency is evaluated on reasonable possibility of material misstatement, individually and in aggregate, which is how several minor ITGC issues in one layer become a significant deficiency.

Criticality, effort and weighted coverage

Criticality is scored 1–5 on breach-determinative impact: 5 means an incident becomes materially worse without it, 2 means it is supporting or inherited. Use it to sequence, not to justify skipping.

Effort is calendar time to a working, evidenceable control for an organisation of the stated size — not engineering days. Weighted coverage in the strip above weights each control marked in place by its criticality, so closing five score-5 controls moves it more than closing five score-2 controls.